:

HOLLOWGRAPH MALWARE HIJACKS MICROSOFT 365 FOR C2

SECURITY DESK1 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A newly discovered malware component called HollowGraph exploits Microsoft 365 calendar features to communicate with attackers. The malware uses compromised mailboxes as a covert command-and-control channel.

Security researchers have identified HollowGraph, a malicious component that weaponizes Microsoft Graph API to establish hidden communication channels within Microsoft 365 environments. The malware leverages the calendar feature in compromised mailboxes to receive commands from attackers and exfiltrate stolen data. By operating through legitimate Microsoft services, HollowGraph evades traditional security detection mechanisms that typically monitor external network traffic. The use of Microsoft Graph API represents an increasingly common evasion technique. Attackers abuse legitimate cloud services to blend malicious activity with normal business operations, making detection significantly more difficult for defenders. Organizations using Microsoft 365 should review mailbox access logs, monitor for suspicious calendar modifications, and ensure multi-factor authentication is enabled across all accounts. Security teams should also monitor API usage patterns for anomalous behavior indicative of compromised credentials.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A child sexual abuse survivor has filed a lawsuit against Elon Musk's AI company, alleging that Grok generated new illegal pornographic images using pictures of her abuse. Musk denied awareness of the chatbot producing such content.

JUST NOWAI Desk

A UNICEF survey of 21,000 internet-using children across 21 countries found nearly one in five experienced tech-facilitated sexual exploitation and abuse. The report reveals a critical gap in reporting, with less than 1% of cases reaching authorities.

5H AGOSecurity Desk

A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.

11H AGOIndustry Desk

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.

14H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.